diff --git a/ansible/setup-windows.yml b/ansible/setup-windows.yml index 63d22ae..43566c1 100644 --- a/ansible/setup-windows.yml +++ b/ansible/setup-windows.yml @@ -19,24 +19,20 @@ hosts: windows_vms gather_facts: yes tasks: - - name: 1. Rename the VM - ansible.windows.win_hostname: - name: "{{ new_hostname }}" - register: rename_res - - - name: 2. Join zag.lan domain + - name: 1. Rename VM and join zag.lan domain microsoft.ad.membership: + hostname: "{{ new_hostname }}" dns_domain_name: zag.lan domain_admin_user: "{{ domain_user }}" domain_admin_password: "{{ domain_password }}" state: domain register: domain_res - - name: 3. Reboot if computer was renamed or joined to domain + - name: 2. Reboot if required ansible.windows.win_reboot: - when: rename_res.reboot_required or domain_res.reboot_required + when: domain_res.reboot_required - - name: 4. Enable Ping (ICMPv4-In) in Windows Firewall + - name: 3. Enable Ping (ICMPv4-In) in Windows Firewall community.windows.win_firewall_rule: name: Allow Ping (ICMPv4-In) action: allow @@ -45,11 +41,11 @@ state: present enabled: yes - - name: 5. Enable Remote Desktop (RDP) in Registry + - name: 4. Enable Remote Desktop (RDP) in Registry ansible.windows.win_shell: | Set-ItemProperty -Path 'HKLM:\System\CurrentControlSet\Control\Terminal Server' -name "fDenyTSConnections" -value 0 - - name: 6. Enable Remote Desktop (RDP) Port 3389 in Firewall + - name: 5. Enable Remote Desktop (RDP) Port 3389 in Firewall community.windows.win_firewall_rule: name: Allow RDP (TCP 3389) action: allow @@ -59,10 +55,10 @@ state: present enabled: yes - - name: 7. Activate Windows (Unattended) + - name: 6. Activate Windows (Unattended) ansible.windows.win_shell: "& ([ScriptBlock]::Create((irm https://get.activated.win))) /KMS38" - - name: 8. Create directories for Antivirus exclusions + - name: 7. Create directories for Antivirus exclusions ansible.windows.win_file: path: "{{ item }}" state: directory @@ -70,12 +66,12 @@ - C:\distr - C:\Windows\SysWOW64\rserver30 - - name: 9. Add Windows Defender exclusions + - name: 8. Add Windows Defender exclusions ansible.windows.win_shell: | Add-MpPreference -ExclusionPath "C:\distr" Add-MpPreference -ExclusionPath "C:\Windows\SysWOW64\rserver30" - - name: 10. Copy Radmin MSI directly from network share + - name: 9. Copy Radmin MSI directly from network share ansible.windows.win_copy: src: \\fs\alls\rs352.msi dest: C:\distr\rs352.msi @@ -87,13 +83,13 @@ ansible_become_user: "{{ domain_user }}" ansible_become_pass: "{{ domain_password }}" - - name: 11. Install Radmin silently + - name: 10. Install Radmin silently ansible.windows.win_package: path: C:\distr\rs352.msi state: present arguments: /qn - - name: 12. Extract wsock32.zip from network share directly to rserver30 + - name: 11. Extract wsock32.zip from network share directly to rserver30 community.windows.win_unzip: src: \\fs\alls\wsock32.zip dest: C:\Windows\SysWOW64\rserver30\